Privacy Policy

Last updated: January 1, 2025

Introduction

PictoHouse SAS (hereinafter "we", "our" or "PictoHouse") respects your privacy and is committed to protecting your personal data. This privacy policy describes how we collect, use and protect your personal information in accordance with the General Data Protection Regulation (GDPR) and applicable laws.

This policy applies to all users of our PictoHouse platform, whether they are website visitors, registered users or customers.

Data Controller


PictoHouse SAS
123 Rue de l'Innovation, 75001 Paris, France
Email: privacy@pictohouse.com
Phone: +33 1 23 45 67 89

Data collected

We collect different types of personal data depending on your use of our services:

Identification data


• First and last name
• Email address
• Phone number
• Company name
• Postal address (for billing)

Connection data


• Login credentials
• Passwords (hashed and secured)
• IP addresses
• Approximate geolocation data
• Device and browser information

Usage data


• Created videos and their content
• Uploaded photos
• Customization preferences
• Platform usage history
• Billing and payment data

Technical data


• Cookies and similar technologies
• Connection logs
• Performance data
• Error information

Purposes and legal bases for processing

We process your personal data for the following purposes:

Contract execution


• Creation and management of your account
• Provision of video creation services
• Payment processing
• Customer support
• Service-related communications

Legitimate interests


• Improvement of our services
• Statistical and usage analysis
• Platform security
• Fraud prevention
• Direct marketing (if you have not withdrawn your consent)

Consent


• Newsletters and marketing communications
• Non-essential cookies
• Testimonials and case studies

Legal obligations


• Retention of billing data
• Tax declarations
• Responses to authority requests

Data usage

Your data is used for:

Service provision


We use your data to provide our video creation services, manage your account, process your payments and offer you quality customer support.

Continuous improvement


We analyze the use of our platform to improve our services, develop new features and optimize the user experience.

Communication


We send you communications related to your account, service updates and, if you have consented, newsletters and promotional offers.

Security


We use your data to protect our platform against abuse, fraud and malicious activities.

Legal compliance


We process certain data to comply with our legal obligations, particularly in terms of accounting and taxation.

Data sharing

We never sell your personal data. We may share it in the following situations:

Service providers


We work with trusted providers for:
• Hosting (Vercel, AWS)
• Payment processing (Stripe)
• Email marketing (SendGrid)
• Audience analysis (Google Analytics)
• Customer support (Intercom)

Legal obligations


We may disclose your data if required by law or to:
• Respond to a subpoena or court order
• Protect our legal rights
• Investigate potential fraud
• Protect the security of our users

Business transfers


In case of merger, acquisition or asset sale, your data could be transferred to the new owner.

Consent


We may share your data with your explicit consent for specific purposes.

Retention period

We retain your personal data for the following periods:

Active accounts


As long as your account is active and for 3 years after last use.

Billing data


10 years after the last invoice, in accordance with accounting obligations.

Marketing data


Until you unsubscribe or 3 years after your last interaction.

Cookies


According to your browser settings, generally 13 months maximum.

Security logs


1 year for fraud detection and prevention.

Support data


5 years after resolution of the last ticket to ensure service continuity.

At the expiration of these periods, your data is securely deleted or anonymized.

Your rights

In accordance with GDPR, you have the following rights:

Right of access


You can request a copy of all personal data we hold about you.

Right of rectification


You can request correction of inaccurate or incomplete data.

Right to erasure ("right to be forgotten")


You can request deletion of your data in certain circumstances.

Right to restrict processing


You can request suspension of processing of your data.

Right to data portability


You can receive your data in a structured and readable format.

Right to object


You can object to the processing of your data for legitimate reasons.

Right to withdraw consent


You can withdraw your consent at any time.

How to exercise your rights


To exercise these rights, contact us at: privacy@pictohouse.com
We will respond within a maximum of 30 days.

Right to lodge a complaint


You have the right to file a complaint with the CNIL: www.cnil.fr

Data security

We implement appropriate technical and organizational measures to protect your data:

Encryption


• TLS/SSL encryption for all transmissions
• Encryption of sensitive data in database
• Secure password hashing

Access controls


• Multi-factor authentication
• Restricted data access based on needs
• Regular access auditing

Infrastructure


• Hosting with certified providers
• Regular and secure backups
• Continuous system monitoring

Procedures


• Security training for staff
• Strict confidentiality policy
• Incident response plan
• Regular security testing

Despite these measures, no system is 100% secure. In case of data breach, we will inform you within 72 hours.

International transfers

Some of your data may be transferred to countries located outside the European Union:

Protection guarantees


All transfers are made with appropriate safeguards:
• Standard contractual clauses from the European Commission
• Privacy Shield certifications (for US companies)
• Adequacy decisions from the European Commission

Providers concerned


• Hosting services (United States)
• Analytics services (United States)
• Customer support (European Union)

You can request more information about these transfers by contacting us.

Cookies and similar technologies

We use cookies and similar technologies. For more information, see our Cookie Policy.

Types of cookies


Essential: Necessary for site operation
Functional: Improve your experience
Analytics: Help us understand usage
Marketing: Personalize advertising

Preference management


You can manage your cookie preferences via:
• Our preference center
• Your browser settings
• Specific opt-out tools

Changes to this policy

We may modify this privacy policy to reflect:
• Changes to our services
• Legal or regulatory changes
• Industry best practices

Change notification


In case of significant changes:
• We will inform you by email
• We will display a notice on our site
• We will request your consent if necessary

We encourage you to regularly review this policy.

Contact us

For any questions regarding this privacy policy or your personal data:

Data Protection Officer


Email: dpo@pictohouse.com

Customer service


Email: privacy@pictohouse.com
Phone: +33 1 23 45 67 89

Postal address


PictoHouse SAS - Privacy Department
123 Rue de l'Innovation
75001 Paris, France

We are committed to responding to all your requests within 30 days.